This document describes the management of vulnerabilities for the project and all modules within the organization.
A package import sends environment variables to an obscured remote endpoint and executes its response. This is a confirmed import-time remote-code-execution and data-exfiltration surface.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/initializeCaller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/initializeCaller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/initializeCaller.jsView on unpkgThe initializer sends the complete process environment to a Base64-obscured external endpoint.
lib/initializeCaller.jsView on unpkg · L7The response body is compiled and executed with access to require, enabling remote code execution.
lib/initializeCaller.jsView on unpkg · L13Package source references a known benign dynamic code generation pattern.
lib/initializeCaller.jsView on unpkg · L12Importing the declared entry point immediately loads the hidden initializer.
index.jsView on unpkg · L7This report applies to chai-as-viem@1.1.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/initializeCaller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/initializeCaller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/initializeCaller.jsView on unpkgThe initializer sends the complete process environment to a Base64-obscured external endpoint.
lib/initializeCaller.jsView on unpkg · L7The response body is compiled and executed with access to require, enabling remote code execution.
lib/initializeCaller.jsView on unpkg · L13Package source references a known benign dynamic code generation pattern.
lib/initializeCaller.jsView on unpkg · L12Importing the declared entry point immediately loads the hidden initializer.
index.jsView on unpkg · L7